


Perceptive Security
SOC/SIEM Consultancy

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the…
Published:
3 April 2026 at 22:00:00
Alert date:
4 April 2026 at 15:05:07
Source:
nvd.nist.gov
Security Tools
CVE-2016-20061 affects Sheed AntiVirus 2.3, containing an unquoted service path vulnerability in the ShavProt service. Local attackers can exploit this vulnerability to escalate privileges by inserting a malicious executable in the unquoted path. When the service restarts or system reboots, the malicious code executes with LocalSystem privileges. This vulnerability allows for privilege escalation attacks on systems running the affected antivirus software. The vulnerability has been documented with proof-of-concept exploits available.
Technical details
Mitigation steps:
Affected products:
Sheed AntiVirus
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2016-20061
http://dl.sheedantivirus.ir/setup.exe
http://sheedantivirus.ir/
https://www.exploit-db.com/exploits/40497
https://www.vulncheck.com/advisories/sheed-antivirus-unquoted-service-path-privilege-escalation
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
